An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in pr...
Description
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation
AI Analyst Comment
Remediation
Update to patched version immediately. Review user permissions and access controls.
---METADATA---
VENDOR: F5
PRODUCT: BIG-IP
AFFECTED_VERSIONS: F5 BIG-IP: 21.0.0 up to (excluding) 21.0.0.2, 17.5.0 up to (excluding) 17.5.1.6, 17.1.0 up to (excluding) 17.1.3.2, 16.1.0 and later
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An authenticated Resource Administrator or Administrator can modify configuration objects via iControl SOAP, leading to privilege escalation in F5 BIG-IP.
Executive Summary:
An authenticated privilege escalation vulnerability in F5 BIG-IP allows administrative users to modify system configurations, posing a significant risk to infrastructure integrity.
Vulnerability Details
CVE-ID: CVE-2026-40631
Affected Software: F5 BIG-IP
Affected Versions: F5 BIG-IP: 21.0.0 up to (excluding) 21.0.0.2, 17.5.0 up to (excluding) 17.5.1.6, 17.1.0 up to (excluding) 17.1.3.2, 16.1.0 and later
Vulnerability: This is a CWE-552 vulnerability where configuration objects are improperly accessible. The attack requires the user to have already obtained Resource Administrator or Administrator privileges, meaning this is an escalation of privilege from an already high-privileged account.
Business Impact
The ability for an administrator to modify arbitrary configuration objects could lead to complete system compromise, unauthorized traffic redirection, or the disabling of security controls. With a CVSS score of 8.7, this vulnerability represents a high-severity risk to business continuity and data confidentiality, as it bypasses intended access control limitations within the administrative interface.
Remediation Plan
Immediate Action: Update F5 BIG-IP installations to version 21.1.0 or later, as provided in the vendor's security advisory.
Proactive Monitoring: Review iControl SOAP access logs for unusual configuration change patterns or administrative actions performed by service accounts.
Compensating Controls: Restrict access to the iControl SOAP interface to trusted management IP addresses and enforce strict multi-factor authentication (MFA) for all administrative accounts.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of May 14, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The requirement for pre-existing administrative privileges limits the attack surface to malicious insiders or compromised administrative credentials.
Analyst Recommendation
Given the severity of the potential impact, organizations should prioritize patching F5 BIG-IP systems during the next maintenance window. Administrators must ensure that only authorized personnel have high-level access to the iControl SOAP interface to prevent exploitation of this privilege escalation flaw.